CVE-2013-0074
KEV RANSOMWAREHIGH 9.3EPSS 81.9%
Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka "Silverlight Double Dereference Vulnerability."
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 81.87% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-05-25, used in ransomware campaigns
- Published
- 2013-03-13
- Updated
- 2026-08-14
Proof-of-concept exploits (4)
- TwoPt4Mhz/Hun73r0★ · 2016-12-22
- likekabin/CapTipper-original_https-capture0★ · 2018-07-17
- likescam/CapTipper-original_https-capture0★ · 2018-07-17
- omriher/CapTipper726★ · 2023-03-16